Insider Threat Matrix™Insider Threat Matrix™
  • ID: DT106
  • Created: 14th December 2024
  • Updated: 23rd July 2026
  • Contributor: The ITM Team

Microsoft Entra ID Privileged Identity Management Resource Audit

Within the Microsoft Entra admin center, the Resource audit can be reviewed to identify PIM elevations for users, including key information such as the requestor user, subject user, action, domain, and primary target (role assigned/removed). This can aid investigators by providing an audit trail for PIM elevations and the duration for which an eligible role was attached to a user account.

 

The following URL can be used to view this activity log, provided the investigator's account has the Privileged Role Administrator role assigned, or a role with higher privileges: https://entra.microsoft.com/#view/Microsoft_Azure_PIMCommon/ResourceMenuBlade/~/Audit/resourceId//resourceType/tenant/provider/aadroles

Sections

ID Name Description
PR024Privilege Elevation

The subject activates, obtains, or creates an execution, identity, or authorization context that provides greater effective access than their normal operating context. The elevated context may be available through permissions legitimately assigned to the subject, or obtained through misuse, circumvention, identity manipulation, credential acquisition, or exploitation of a technical vulnerability.

 

Privilege elevation is preparatory where it increases the subject’s capability to access restricted systems or data, modify protected configurations, disable controls, or perform a later infringement. Routine elevation conducted for an approved and attributable operational task should not be classified under this Section. Investigators should assess whether the mechanism was available to the subject, whether its activation was approved, and how the elevated context was subsequently used.

PR018Circumventing Security Controls

A subject abuses their access or conducts unapproved changes to circumvent security controls.

IF011Providing Access to a Unauthorized Third Party

A subject intentionally provides system or data access to a third party that is not authorized to access it.

PR015.004Bulk Email Collection

A subject creates an email collection file such as a Personal Storage Table (PST) file or an MBOX file to copy an entire mailbox or subset of a mailbox containing sensitive information.

ME024.002Access to Privileged Groups and Non-User Accounts

A subject with access to privileged groups (e.g., Domain Admins, Enterprise Admins, or Security Groups) or non-user accounts (such as service accounts, application identities, or shared mailboxes) gains elevated control over systems, applications, and sensitive organizational data. Access to these groups or accounts often provides the subject with knowledge of security configurations, user roles, and potentially unmonitored or sensitive activities that occur within the system.

 

Shared mailboxes, in particular, are valuable targets. These mailboxes are often used for group communication across departments or functions, containing sensitive or confidential information, such as internal discussions on financials, strategic plans, or employee data. A subject with access to shared mailboxes can gather intelligence from ongoing conversations, identify targets for further exploitation, or exfiltrate sensitive data without raising immediate suspicion. These mailboxes may also bypass some security filters, as their contents are typically considered routine and may not be closely monitored.

 

Access to privileged accounts and shared mailboxes also allows subjects to escalate privileges, alter system configurations, access secure data repositories, or manipulate security settings, making it easier to both conduct malicious activities and cover their tracks. Moreover, service and application accounts often have broader access rights across systems or environments than typical user accounts and are frequently excluded from standard monitoring protocols, offering potential pathways for undetected exfiltration or malicious action.

 

This elevated access gives subjects insight into critical system operations and internal communications, such as unencrypted data flows or internal vulnerabilities. This knowledge not only heightens their potential for malicious conduct but can also make them a target for external threat actors seeking to exploit this elevated access.

IF039.002Access to a Retained Former Account

A subject accesses or uses an account that was previously issued to them by the organization but is no longer authorized for their use. This may occur after employment has ended, a contract has expired, a role has changed, a project has concluded, or access has otherwise ceased to be permitted.

 

This behavior may involve the subject using retained credentials, active sessions, multi-factor authentication enrollment, recovery options, device trust, federated access, cached authentication material, or connected service access after authorization has ended. The defining behavior is that the subject continues to access an account that they were once permitted to use but are no longer authorized to access.

PR024.002Privilege Activation

The subject activates elevated permissions that are assigned to them or conditionally available through an established organizational or operating-system mechanism. This may include sudo, an elevation prompt, just-in-time access, privileged identity management, cloud role assumption, or an equivalent governed process.

 

The activation may itself be approved or unapproved. It should be recorded where entering the elevated context is materially relevant to an investigation, including where an approved mechanism is used outside its authorized purpose or before a later infringement.

PR044.004Cloud Identity Discovery

A subject identifies or enumerates users, groups, roles, guest identities, service principals, managed identities, application identities, or other accounts maintained within a cloud environment.

 

The subject may use a cloud administration portal, command-line interface, software development kit, application programming interface, identity platform, or script to retrieve identity and access information. The resulting data may include account names, role assignments, group memberships, authentication methods, account status, tenant relationships, or access to cloud resources.

 

Cloud identity discovery may enable later credential collection, privilege elevation, unauthorized cloud access, impersonation, persistence, or movement between subscriptions, projects, accounts, tenants, or services. Investigators should examine cloud control-plane audit events, identity-listing operations, query volume, resources queried, originating identity, and subsequent activity involving discovered accounts or roles.

PR044.006Privileged and High-Value Account Discovery

A subject specifically identifies or enumerates privileged, administrative, executive, security, dormant, emergency, or other high-value organizational identities.

 

The subject may search for membership of administrative groups, privileged cloud roles, domain administrators, security personnel, executive accounts, service accounts with elevated access, emergency access identities, or accounts with authority over sensitive systems and business processes.

 

This behavior is distinct from broad account discovery because the subject selectively targets identities whose authority, access, organizational position, or reduced oversight could support a later infringement. The discovered identities may be targeted for credential collection, impersonation, privilege elevation, persistence, unauthorized approval, or anti-forensic account misuse.

 

Investigators should examine the names, roles, groups, and attributes queried; whether the subject searched for terminology associated with elevated access; and whether the activity was followed by credential access, authentication attempts, social engineering, or requests involving the identified accounts.

AF034.004Disable Cloud and Identity Audit Logging

A subject disables or materially weakens native audit logging within a cloud platform, identity provider, cloud account, subscription, project, tenant, or Software as a Service environment.

 

The subject may disable audit services, remove data-event categories, alter diagnostic settings, disable identity or administrative audit events, exclude resources from monitoring, or change the destination to which native audit records are sent. The activity may affect cloud control-plane actions, resource access, authentication, role assignments, application administration, or other security-relevant events.

 

Investigators should review provider-maintained administrative records, privileged-role activation, configuration changes, logging-resource changes, policy modifications, and discrepancies between native audit sources and exported records.